Skip to main content

Share story

Security Infrastructure

Researchers identify more than 3400 servers hit by PoeLLM mining malware

Researchers identify more than 3400 servers hit by PoeLLM mining malware Image: Primary
Lumen Black Lotus Labs identified more than 3400 victim servers in a cryptocurrency-mining campaign targeting exposed AI services and other enterprise systems, The Hacker News reported. The campaign, active since April 2026, installs miners and reuses compromised hosts to scan for and exploit additional victims. The PoeLLM malware derives its command-server address from changing words in a poem hosted on GitHub. Targets include LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances, with infections concentrated in the US and Western Europe. Recent traffic suggests experiments with distributed password guessing, whose maturity remains uncertain.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Science Security
Science Security

Preprint finds sensitive-topic leakage in AI model routing logs

Researchers report in a preprint that logs recording which AI model handles a request can expose sensitive-topic patterns even when content logging is disabled. Their studies used 1.7 million real requests and tested systems that ...

Security Infrastructure
Security Infrastructure

IDCF Cloud ransomware attack disrupts companies and local governments

A ransomware attack disrupted IDCF Cloud's East Japan Region 1 on October 7, affecting websites and services used by companies and local governments. A note article citing ITmedia and Nikkei reports said unauthorized access began ...

Security Infrastructure
Security Infrastructure

Registry breaches let attackers hijack domains and obtain HTTPS certificates

Attackers compromised third-party operators for Ghana's .GH, Sierra Leone's .SL and American Samoa's .AS domains, changed authoritative DNS records and obtained unauthorized HTTPS certificates, BleepingComputer reported. Google do...

Security Products
Security Products

Outlook will block Windows installer attachments by default

Microsoft will block .msix and .msixbundle attachments by default in Outlook on the web and the new Outlook for Windows. The rollout to Exchange Online users starts in early November and is expected to reach general availability b...